- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Bastian Germann
- Date:
- 2026-07-28 17:55:01 UTC
- Severity:
- normal
- Tags:
[ Reason ] 9 open CVE issues in trixie that are fixed in testing. [ Impact ] Users are vulnerable to the security issues. [ Tests ] I (sponsor) have only build-tested this on amd64. The submitter may have done additional tests and I have asked him to submit additional details. [ Risks ] (Discussion of the risks involved. E.g. code is trivial or complex, alternatives available.) [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in stable [x] the issue is verified as fixed in unstable [ Changes ] This includes the upstream patches from the stable 3.10 tree that are marked to fix the CVEs and apply cleanly on the trixie version.
Thank you Bastian for filing this patch request. This patch series should address the request in bug#1142507. I've built, locally, a new package with this patch series and I'm currently running it successfully on my deployment. The stack is stable and I did not observe any regression as a result of these patches. I did not try to explicitly reproduce nor test the bugs described in the CVSs beyound the unit tests attached to the patches provided. Please let me know if you need any additional info. Thank you.